App Review AppGuard on Windows 10- An Unconventional Use

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,144
I’ve discussed at some length elsewhere why it’s difficult to formulate a legitimate test of AppGuard, so won’t repeat it here. Although I’m sure I can develop some protocol that is fair and unbiased in the future, in the meantime I’d like to present this one (a pruduct of free time and 3 or 4 glasses of wine).

While watching keep in mind a few things:

1). It’s not a difficult thing for Scriptor malware to get by a primary traditional security solution (like in this video),
2). and as was illustrated in a test in late May, the commonly used second opinion scanners aren’t very good at detecting the primary vector, no less the spawn that establishes itself on the system, and
3). a Scriptor can be coded to make itself Hidden and autostart by various means (like most Worms).

For all of the reasons above one can see that cleaning an infected system may not be at all straightforward.

The question is can AppGuard cleanup easier?

 

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
All I can say is that AppGuard rocks!

cruelsister is absolutely right that AppGuard could definitely fight malware even if the computer was infected first.
 
  • Like
Reactions: Deleted member 178

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
Well it sure looks like AppGuard does a fine job in the demo. ;)
The malware authors didn't yet realize that AppGuard blocks and protects in the user-space. :D

I think that AppGuard will be easy to circumvent especially when the computer will be infected first. All the malware must do is to install in the system-space like a legitimate software. After that, AppGuard, when installed, won't be able to touch the malware. :)
Unless, of course, the user would put the malware under Guarded Applications.

So, this would be a limitation of AppGuard.
 

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,144
Guru- Windows Defender takes advantage of AMSI on Win10, so in this case is is superior. Regarding Panda- whenever I need an AV to use in a demonstration that I know will let the system become infected Panda is right up there with FortiClient as my go-to product.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top